[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Fwd: Re: Son of IKE: A proposal for moving forward



On Thu, 13 Jun 2002, Bill Sommerfeld wrote:
> > There is no reason why the two trusted "networks" can't be single hosts --
> > that's just a degenerate case...
> 
> there are certain obvious scaling problems with this approach.
> direct use of transport mode is likely to be easier to manage, require
> fewer addresses, and be simpler with large numbers of hosts.

You're making unwarranted assumptions about what a VPN is.  It's perfectly
possible to have a VPN in which the "wires" are private but the addresses
are not.  (Indeed, even VPNs with non-degenerate ends do not necessarily
use private addresses.)

                                                          Henry Spencer
                                                       henry@spsystems.net